Описание
Lavalite vulnerable to Arbitrary File Read via Directory Traversal
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
Пакеты
Наименование
lavalite/cms
composer
Затронутые версииВерсия исправления
= 9.0.0
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
больше 3 лет назад
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.